EasyManuals Logo

H3C S5120-SI Series User Manual

H3C S5120-SI Series
697 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #498 background imageLoading...
Page #498 background image
1-4
A referenced time range can be one that has not been created yet. The rule, however, can take effect
only after the time range is defined and becomes active.
IP Fragments Filtering with ACL
Traditional packet filtering performs match operation on, rather than all IP fragments, the first ones only.
All subsequent non-first fragments are handled in the way the first fragments are handled. This causes
security risk as attackers may fabricate non-first fragments to attack your network.
As for the configuration of a rule of an IPv4 ACL, the fragment keyword specifies that the rule applies to
non-first fragment packets only, and does not apply to non-fragment packets or the first fragment
packets. ACL rules that do not contain this keyword is applicable to both non-fragment packets and
fragment packets.
ACL Application
ACLs are widely used in technologies. One typical application is to apply different types of ACLs for
traffic filtering. For details, refer to
ACL Application for Packet Filtering.
In addition, ACLs can be used in such fields as routing, security, and QoS. For configuration details,
refer to the related parts of this configuration manual.

Table of Contents

Other manuals for H3C S5120-SI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the H3C S5120-SI Series and is the answer not in the manual?

H3C S5120-SI Series Specifications

General IconGeneral
BrandH3C
ModelS5120-SI Series
CategorySwitch
LanguageEnglish

Related product manuals